In a significant cybersecurity maneuver, the FBI has announced the successful removal of Chinese malware from 4,258 U.S.-based computers and networks. This was achieved through issuing commands that triggered the malware’s own “self-delete” function.
The malware, developed by the Mustang Panda group at the behest of the People’s Republic of China, utilized a variant of PlugX. This software enabled hackers to gain control over and extract data from compromised systems, targeting U.S. victims as well as European and Asian governments, businesses, and Chinese dissident factions since at least 2014. Although known for several years, the PlugX malware continued to infect numerous Windows computers whose owners remained largely unaware.
The FBI’s ability to neutralize the threat was informed by a strategy developed by a French law enforcement agency. This agency had previously gained access to a command-and-control server enabling them to communicate with and send commands to infected machines.
According to the FBI, the PlugX malware was designed to submit a communication request to a command-and-control (C2) server, the IP address for which was embedded within the malware itself. Upon receiving a corresponding command from the C2 server, the affected malware could execute its “self-delete” command, effectively erasing itself, its generated files, and registry keys that facilitated its automatic re-launch upon system startup.
The FBI detailed the operation in an affidavit made available on December 20 and unsealed just recently. This action underscores ongoing international cooperation in the realm of cybersecurity and the persistent threat posed by state-sponsored cyber operations. For more detailed coverage of this incident, the original article can be accessed here.